Privacy Policy
Last updated: July 2026
1. What we collect
- Account info: name, email, and (if you sign in with Google) your Google profile info.
- Content you provide: website descriptions, follow-up answers, uploaded voice recordings (processed for transcription, not stored as audio), generated code and its version history, SEO settings, and any custom domains you connect.
- Billing info: handled directly by Paddle, our payment processor — we don't see or store your card details ourselves.
- Usage data: which features you use and how many credits you spend, kept in a credit ledger and an audit log of security-relevant account events (logins, plan changes, deletions).
- If you connect Vercel: an access token allowing us to deploy on your behalf, until you disconnect it.
2. How we use it
To operate webma: authenticate you, generate and store your websites, process payments, enforce plan limits, provide customer support, and maintain security (including the audit log). We don't sell your data.
3. Who we share it with
Only the processors needed to run the service:
- Supabase — hosts our database and handles authentication.
- Google Gemini and OpenAI — process your website descriptions and voice recordings to generate content. Your prompts may be cached (as a task+prompt hash, not linked to your identity) to avoid re-billing identical requests.
- Paddle — processes payments and, as merchant of record, handles applicable sales tax/VAT. See Paddle's own privacy policy for how they handle payment data.
- Vercel — host deployed sites, either under our platform account or yours if you've connected one.
We don't share your data with anyone else, except where required by law.
4. Your rights
You can view and update your profile info from your account settings. You can permanently delete your account — including all projects, subscription data, and connected integrations — at any time from Settings; this is irreversible. If you're in a jurisdiction with statutory data rights (GDPR, CCPA, or similar), you may also have a right to request a copy of your data or object to certain processing — contact us to exercise these.
5. Data retention
We keep your account and project data for as long as your account is active. Audit log entries (security-relevant events) are retained separately for accountability purposes even after related records change. Deleting your account removes your projects, subscription, and connections; some records may be retained where we're legally required to (e.g. payment records for tax purposes, handled by Paddle).
6. Security
We use row-level security so your data is only ever accessible to your own account (or an administrator, for support purposes) at the database level, encrypted connections throughout, and optional two-factor authentication you can enable from Settings.
7. Cookies
We use essential cookies for authentication (session management via Supabase Auth). We don't currently use tracking or advertising cookies.
8. Changes to this policy
We may update this policy from time to time; material changes will be communicated before they take effect.
9. Contact
Questions or data requests: techtig9@gmail.com